Did the read me, looking for some help.

Discussion in 'Malware Help (A Specialist Will Reply)' started by damican, Feb 18, 2010.

  1. damican

    damican Private E-2

    Ok, so I did the read me and I think it got rid of some stuff, but probably not completely so I'm looking for some help!

    I'mr unning 64bit so I didnt use the two programs that said DONT USE haha. Help will be vastly appreciated.

    edit: I'm not really sure what the initial problem was, but I know it was something bad. It made IE open up (but not that I could see) and run crap, anytime I would close it through task manager it would reopen itself. I disabled IE, ran malware bytes(which didnt want to initially run until I renamed the .exe file) and removed some crap, still having some problems I did the read me and here I am.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    btdna.exe
    SUPERAntiSpyware.exe
     
    :Files
    C:\ProgramData\zofowoda\zofowoda.dll
    C:\Users\new user\AppData\Local\micwmod.dll
    C:\Users\new user\AppData\Local\Temp\aez5vk.exe
    C:\Users\new user\AppData\Local\Temp\lsass.exe
    c:\PROGRA~3\jefotumo\jefotumo.dll
    C:\ProgramData\zofowoda
    c:\PROGRA~3\jefotumo
     
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "kovurofop"=-
    "BitTorrent DNA"=-
     
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "hugatovone"=-
    "Exedejemila"=-
    "uishf9wuifwuh387fh3wufinhjfdwefe"=-
    "kovurofop"=-
    "asg984jgkfmgasi8ug98jgkfgfb"=-
     
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "DisableRegistryTools"=-
    "DisableTaskMgr"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "DisableRegistryTools"=-
    "DisableTaskMgr"=-
     
    :Commands
    [purity]
     
    [EmptyTemp]
    [start explorer]
    [Reboot]
     
     
    
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. damican

    damican Private E-2

    Well, now when I restart I dont get error messages saying a couple of dll files (some random letter jibberish that was removed) cant be found. Hopefully everything is all cleared up! (I am very happy this also got rid of a some annoying arse search word popups. Even in the readme some of the words would be green and if I highlighted them it would pop up some little search bar in a pip thing.)

    What exactly was messing my PC up anyways?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You had several different infections including the below:
    Trojan.Hiloti
    Trojan.Agent
    Trojan.Unclassified/Packed-Win
    Adware.Vundo/Variant


    And you still have some remnants of these infections to remove.

    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of the code box
    Code:
    :Files
    C:\ProgramData\dasabisi
    C:\ProgramData\favayoko
    C:\ProgramData\kedisuzo
    C:\ProgramData\lelasuba
    C:\ProgramData\siveraja
     
    :Commands
    [EmptyTemp]
    [start explorer]
    [Reboot]
    
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. damican

    damican Private E-2

    The little green highlights under certain words were back, but now they've disappeared :/

    I've tried to cut my browsing down to sites I trust pretty much. Though, I'm thinking about not using megavideo as it likes to throw popups at me. Thanks for the help man, I appreciate it.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These are not malware. They are Vibrant Media Ads which are quite common on many websites. It helps to keep the websites in operation by paying some of the bills. ;)


    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. .
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds